IP Library › Granted Patent US 12,425,861
Granted Patent B2
US 12,425,861 · App. 17/245,570 · Granted Sep 23, 2025

Method for determining class information and apparatus

Inventors: Li Hu (Shanghai, CN); Jing Chen (Shanghai, CN)
Assignee: Huawei Technologies Co., Ltd.
H04W12/12H04L63/1416H04L63/1425H04W48/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,861
App. No.
17/245,570
Filed
Apr 30, 2021
Granted
Sep 23, 2025
Kind
B2
Art Unit
2494
USPC
726/3
Abstract

This application provides example methods and apparatuses for determining class information. One example method includes sending, by a security detection function network element, a subscription data collection event to a mobility management network element, where the subscription data collection event includes a collection range and a reporting condition. The security detection function network element can then receive a data collection service response message from the mobility management network element, where the data collection service response message includes first class information and first traffic data corresponding to the first class information, and where the first traffic data meets the reporting condition. The security detection function network element can then determine abnormal class information based on the first traffic data. The security detection function network element can then send the abnormal class information to a policy control network element.

Claims (46)

1. A method for determining class information, comprising:

sending, by a security detection function network element, a subscription data collection event to a mobility management network element, wherein the subscription data collection event comprises a collection range and a reporting condition, wherein the collection range indicates that data is collected based on class information of a terminal, and wherein the reporting condition indicates a condition for triggering reporting of traffic data;

receiving, by the security detection function network element, a data collection service response message from the mobility management network element, wherein the data collection service response message comprises first class information and first traffic data corresponding to the first class information, and wherein the first traffic data meets the reporting condition;

determining, by the security detection function network element, abnormal class information based on the first traffic data, wherein the determining comprises determining, based on the first traffic data, at least one parameter indicating whether a distributed denial of service (DDoS) attack occurs; and

sending, by the security detection function network element, the abnormal class information to a policy control network element, wherein flow matching information and a flow processing method are generated, wherein the flow matching information is used to match user plane traffic, and wherein the flow processing method is used to control user plane traffic that matches the flow matching information and that is from a terminal matching the abnormal class information.

2. The method according to claim 1 , wherein the abnormal class information is used to perform access control on a terminal matching the abnormal class information.

3. The method according to claim 1 , wherein the first class information is determined by device information of the terminal.

4. The method according to claim 3 , wherein the device information of the terminal comprises a type allocation code (TAC) of an equipment identification code of the terminal.

5. The method according to claim 1 , comprising:

receiving, by the policy control network element, the abnormal class information from the security detection function network element;

generating, by the policy control network element, the flow matching information and the flow processing method; and

sending, by the policy control network element, the abnormal class information, the flow matching information, and the flow processing method to a session management network element.

6. The method according to claim 5 , wherein the method further comprises:

receiving, by the policy control network element, a victim ID from the security detection function network element, wherein the victim ID identifies an attacked target, and wherein

the generating, by the policy control network element, flow matching information comprises generating, by the policy control network element, the flow matching information based on the victim ID.

7. The method according to claim 5 , wherein the generating, by the policy control network element, flow matching information and a flow processing method comprises:

generating, by the policy control network element, a policy and charging control rule, wherein the policy and charging control rule comprises the flow matching information and the flow processing method.

8. The method according to claim 7 , wherein the policy and charging control rule indicates to discard the user plane traffic that matches the flow matching information and that is from the terminal matching the abnormal class information.

9. A communications apparatus, comprising:

at least one processor; and

one or more memories coupled to the at least one processor and having program instructions stored thereon which, when executed by the at least one processor, cause the apparatus to:

send a subscription data collection event to a mobility management network element, wherein the subscription data collection event comprises a collection range and a reporting condition, wherein the collection range indicates that data is collected based on class information of a terminal, and wherein the reporting condition indicates a condition for triggering reporting of traffic data;

receive a data collection service response message from the mobility management network element, wherein the data collection service response message comprises first class information and first traffic data corresponding to the first class information, and wherein the first traffic data meets the reporting condition;

determine abnormal class information based on the first traffic data, wherein determining the abnormal class information comprises determining, based on the first traffic data, at least one parameter indicating whether a distributed denial of service (DDoS) attack occurs; and

send the abnormal class information to a policy control network element, wherein flow matching information and a flow processing method are generated, wherein the flow matching information is used to match user plane traffic, and wherein the flow processing method is used to control user plane traffic that matches the flow matching information and that is from a terminal matching the abnormal class information.

10. The apparatus according to claim 9 , wherein the abnormal class information is used to perform access control on a terminal matching the abnormal class information.

11. The apparatus according to claim 9 , wherein the first class information is determined based on device information of the terminal.

12. The apparatus according to claim 11 , wherein the device information of the terminal comprises a type allocation code (TAC) of an equipment identification code of the terminal.

13. A non-transitory computer-readable storage medium storing programming instructions for execution by at least one processor, that when executed by the at least one processor, cause a computer to perform operations comprising:

sending, by a security detection function network element, a subscription data collection event to a mobility management network element, wherein the subscription data collection event comprises a collection range and a reporting condition, wherein the collection range indicates that data is collected based on class information of a terminal, and wherein the reporting condition indicates a condition for triggering reporting of traffic data;

receiving, by the security detection function network element, a data collection service response message from the mobility management network element, wherein the data collection service response message comprises first class information and first traffic data corresponding to the first class information, and wherein the first traffic data meets the reporting condition;

determining, by the security detection function network element, abnormal class information based on the first traffic data, wherein the determining comprises determining, based on the first traffic data, at least one parameter indicating whether a distributed denial of service (DDoS) attack occurs; and

sending, by the security detection function network element, the abnormal class information to a policy control network element, wherein flow matching information and a flow processing method are generated, wherein the flow matching information is used to match user plane traffic, and wherein the flow processing method is used to control user plane traffic that matches the flow matching information and that is from a terminal matching the abnormal class information.

14. The non-transitory computer-readable storage medium according to claim 13 , wherein the abnormal class information is used to perform access control on a terminal matching the abnormal class information.

15. The non-transitory computer-readable storage medium according to claim 13 , wherein the first class information is determined by device information of the terminal.

16. The non-transitory computer-readable storage medium according to claim 15 , wherein the device information of the terminal comprises a type allocation code (TAC) of an equipment identification code of the terminal.

17. The non-transitory computer-readable storage medium according to claim 13 , the operations comprising:

receiving, by the policy control network element, the abnormal class information from the security detection function network element;

generating, by the policy control network element, the flow matching information and the flow processing method; and

sending, by the policy control network element, the abnormal class information, the flow matching information, and the flow processing method to a session management network element.

18. The non-transitory computer-readable storage medium according to claim 17 , the operations comprising:

receiving, by the policy control network element, a victim ID from the security detection function network element, wherein the victim ID identifies an attacked target, and wherein

the generating, by the policy control network element, flow matching information comprises generating, by the policy control network element, the flow matching information based on the victim ID.

19. The non-transitory computer-readable storage medium according to claim 17 , wherein the generating, by the policy control network element, flow matching information and a flow processing method comprises:

generating, by the policy control network element, a policy and charging control rule, wherein the policy and charging control rule comprises the flow matching information and the flow processing method.

20. The non-transitory computer-readable storage medium according to claim 19 , wherein the policy and charging control rule indicates to discard the user plane traffic that matches the flow matching information and that is from the terminal matching the abnormal class information.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE SIGNATURE DATE OF INVENTOR JING CHEN PREVIOUSLY RECORDED ON REEL 71313 FRAME 265. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 6, 2025
From: HU, LI; CHEN, JING
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 071491/0687 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2025
From: HU, LI; CHEN, JING
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 071313/0265 →
Priority Claims (1)
CN 201811302764.0 · Nov 2, 2018 · national
Continuity (2)
Continuation PCTCN2019114760 · Oct 31, 2019
Related Publication 20210250771A1 · Aug 12, 2021
References Cited (35)
US 6405318B1 · Rowland · 2002 [cited by applicant]
US 9743269B1 · Yadav · 2017 [cited by examiner]
US 20090013404A1 · Chow · 2009 [cited by examiner]
US 20110016525A1 · Jeong · 2011 [cited by examiner]
US 20120151583A1 · Kang et al. · 2012 [cited by applicant]
US 20130104230A1 · Tang et al. · 2013 [cited by applicant]
US 20160219080A1 · Huang · 2016 [cited by examiner]
US 20160261616A1 · Shulman · 2016 [cited by examiner]
US 20160344696A1 · Yin · 2016 [cited by examiner]
US 20170086090A1 · Sharma et al. · 2017 [cited by applicant]
US 20170250879A1 · Chadha · 2017 [cited by examiner]
US 20180013787A1 · Jiang et al. · 2018 [cited by applicant]
US 20190215305A1 · Monshizadeh · 2019 [cited by examiner]
US 20200028874A1 · Lam · 2020 [cited by examiner]
CN 101453389A · 2009 [cited by applicant]
CN 102404741A · 2012 [cited by applicant]
CN 102447546A · 2012 [cited by applicant]
CN 103269384A · 2013 [cited by applicant]
CN 103297946A · 2013 [cited by applicant]
CN 103918222A · 2014 [cited by applicant]
CN 104270275A · 2015 [cited by applicant]
CN 105812200A · 2016 [cited by applicant]
CN 107835113A · 2018 [cited by applicant]
CN 108347746A · 2018 [cited by applicant]
WO 2018086963A1 · 2018 [cited by applicant]
WO 2018196603A1 · 2018 [cited by applicant]
EPO Partial Supplementary European Search Report issued in European Application No. 198788522.2 on Oct. 27, 2021, 14 pages. [cited by applicant]
3GPP TS 23.122 V15.5.0 (Sep. 2018), “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Non-Access-Stratum (NAS) functions related to Mobile Station (MS) in idle mode (Release … [cited by applicant]
3GPP TS 25.304 V15.0.0 (Jun. 2018), “3rd Generation Partnership Project; Technical Specification Group Radio Access Network; User Equipment (UE) procedures in idle mode and procedures for cell reselection in connected m… [cited by applicant]
LG Electronics, “Clarification on Access control for Rear,” 3GPP TSG-SA WG1 #76, S1-163048, Tenerife, Spain, Nov. 7-10, 2016, 8 pages. [cited by applicant]
Office Action issued in Chinese Application No. 201811302764.0 on Feb. 8, 2022, 13 pages. [cited by applicant]
3GPP TS 23.502 V15.3.0 (Sep. 2018), “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System; Stage 2(Release 15),” Sep. 2018, 329 pages. [cited by applicant]
3GPP TS 23.503 V15.3.0 (Sep. 2018), “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Policy and Charging Control Framework for the 5G System; Stage 2(Release 15),” Sep. 201… [cited by applicant]
Office Action issued in Chinese Application No. 201811302764.0 on Nov. 3, 2020, 35 pages (with English translation). [cited by applicant]
PCT International Search Report and Written Opinion issued in International Application No. PCT/CN2019/114760 on Jan. 23, 2020, 16 pages (with English translation). [cited by applicant]